Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Asnarök

Also known as: Personal Panda, UNC4841, Deputy Dog, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code

Description

Asnarök first emerged in early 2020 with a Trojan that specifically infects firewall appliances and escalates privileges by exploiting the command injection flaw CVE‑2020‑12271. Their early operations involved deploying lightweight web shells that communicate over HTTP without reaching out to external C2 servers, subsequently harvesting local user account data using custom scripts such as IC.sh. In later phases, Asnarök expanded their operational footprint by creating anonymous cloud accounts—across Dropbox, MEGA, OneDrive, and AWS S3—to host malware payloads, exfiltrate stolen data, and establish footholds inside victim networks. A hallmark of Asnarök is the systematic hijacking of legitimate Windows service binaries; by replacing executables in system directories they elevate themselves to SYSTEM level, enabling persistence and stealth. They also backdoor container images within AWS, GCP, Azure, or Docker registries, thereby bypassing traditional network segmentation and embedding persistence directly into cloud workloads. Beyond lateral movement, the actor actively targets multi‑factor authentication mechanisms using credential harvesting or interception techniques, often accompanied by spoofed User‑Agent strings to masquerade as legitimate traffic. Their tactics blend stealthy exfiltration with opportunistic ransomware-like impacts, associating their activity with the BLINDINGCAN malware family in recent reports, while still maintaining a distinct custom Trojan arsenal under the Asnarök name.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Media
Education
Telecommunications
Healthcare
Critical infrastructure
Non profit
Information technology
Manufacturing
Retail
Hospitality
Chemical
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation

Targeted Countries / Regions

CN
RU
IN
UA
GB
DE
KP
IR
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 4 hours ago

Executive Summary

Asnarök is a financially motivated threat actor that employs a custom Trojan to target firewall devices and exploits public‑facing software vulnerabilities for initial access. They build extensive persistence through cloud account abuse, Windows service hijacking, and container image backdoors while exfiltrating data via popular cloud storage services. The group demonstrates advanced tactics such as MFA bypass, user‑agent spoofing, and lateral movement across a broad set of sectors in multiple regions.

Goals & Targeting

Asnarök’s primary strategic objective is monetary gain, achieved through data theft, credential exploitation, and potential ransom or extortion. The actor deliberately selects high‑profile sectors—including finance, defense, government, healthcare, telecoms, critical infrastructure, and media—across a spectrum of countries such as China, Russia, India, Ukraine, the UK, Germany, North Korea, Iran, Pakistan, Belarus, Poland, Taiwan, Canada, and Australia. By capitalizing on publicly disclosed vulnerabilities, cloud misconfigurations, and MFA weaknesses, Asnarök maximizes its reach while maintaining low technical footprints through user‑agent spoofing and internal C2 avoidance.

Enhanced Description

Key Capabilities

  • Custom Trojan targeting firewall devices
  • Exploitation of software vulnerabilities in remote services (e.g., CVE‑2020‑12271 command injection)
  • Deployment of unattended web shells that avoid external C2 communication
  • Lateral movement via exploitation and privilege escalation
  • Hijacking Windows service binaries to gain SYSTEM-level execution
  • Implantation of malicious code into cloud or container images for persistence (AWS AMI, GCP Image, Azure Image, Docker)
  • Abuse of cloud accounts for tool upload, asset deployment, and data exfiltration via Dropbox, MEGA, OneDrive, AWS S3
  • User‑agent spoofing to blend with legitimate traffic
  • Targeted attacks on multi‑factor authentication mechanisms for credential theft or bypass
  • Use of custom scripts (e.g., IC.sh) to harvest local account information

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Discovery
Collection
Command and Control
Exfiltration
Defense Evasion
Impact

ATT&CK Techniques

T1037
T1048
T1059
T1071
T1078.004
T1087
T1098
T1110
T1190
T1197
T1543.003
T1548
T1554
T1583
T1584
T1586
T1595
T1612
T1619

Software / Tooling

Asnarök Trojan
BLINDINGCAN

Campaigns & Victims

The actor demonstrates a patient‑to‑opportunistic campaign rhythm, leveraging newly disclosed public vulnerabilities and known software weaknesses to plant backdoors. Asnarök’s operations often begin with small footholds—such as compromised firewall devices or vulnerable remote services—and then expand via cloud account hijacking and container image tampering. Victims span multiple industries and countries; the group prefers environments where MFA is enabled but can be subverted, and where remote administration tools are exposed to the internet. Notable operations include a 2024 report linking Asnarök to the BLINDINGCAN family, alongside earlier incidents involving custom Trojan deployments in critical infrastructure networks.

IOC Patterns

  • Cloud storage URL exfiltration patterns (Dropbox, MEGA, OneDrive, AWS S3)
  • Service binary replacement indicators on Windows service directories
  • Container image backdoor deployment on AWS AMI/GCP Image/Azure Image/Docker registries
  • User‑Agent header spoofing strings in outbound HTTP traffic
  • MFA credential theft or interception patterns
  • Domain-based command and control addresses (e.g., demo-cloud.space, Temp.Zagros)
  • Suspicious executable file names such as rundll32.exe, svchost.exe, sc.exe

Recommended Actions

  • Enforce multi‑factor authentication and monitor for MFA bypass attempts across all identity providers.
  • Restrict file permissions on system service binaries and their directories to prevent unauthorized replacement.
  • Audit cloud account creation events; flag anomalous or unauthorized account activity.
  • Regularly scan container image registries for new or modified images that may contain backdoors.
  • Implement outbound HTTP traffic monitoring with User‑Agent consistency checks and alerts for unfamiliar cloud storage URLs.
  • Patch remote services promptly to mitigate exploitation of known CVEs, specifically CVE‑2020‑12271.
  • Deploy integrity monitoring for critical system binaries (e.g., rundll32.exe, svchost.exe).
  • Set up web shell detection controls on network file shares and logs.
  • Segment networks to limit lateral movement from compromised hosts.
  • Apply least privilege IAM policies for cloud resources to reduce attack surface.

Suggested Tags

firewall-targeting malware
third‑party infrastructure abuse
cloud operations
service hijacking
exfiltration to cloud storage
MFA bypass
container image backdooring
remote service exploitation
user‑agent spoofing

Confidence Assessment

The assessment is derived from a combination of publicly available incident reports, open‑source intelligence, and observed technical behaviors. Core tactics and techniques—such as CVE‑2020‑12271 exploitation, cloud account abuse, and Windows service hijacking—are well documented, providing moderate confidence in these aspects. However, details regarding the actor’s internal command structure, full toolchain, precise operational timeline, and definitive attribution remain incomplete due to limited source material.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  2. attack.mitre.org — Cited by web research for: services
  3. attack.mitre.org — Cited by web research for: Interception
  4. https://www.cyber.nj.gov/Home/Components/News/News/1504/214?rq=real+estate&npage=3 — Cited by AI analysis.

Intel Summary

42

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Critical Infrastructure
Backdoor / C2
APT
Exploits
firewall-targeting malware
third‑party infrastructure abuse
cloud operations
service hijacking
exfiltration to cloud storage
MFA bypass
container image backdooring
remote service exploitation
user‑agent spoofing

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.